Security Operations Center - Assistant Manager (Noida)

Security Operations Center - Assistant Manager (Noida)

06 Aug
|
KPMG Global Services
|
Noida

06 Aug

KPMG Global Services

Noida

Roles & responsibilities

We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires solid analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.

Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)

Educational Qualifications:

•Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.

•Master's degree in Cybersecurity, Information Security, or related discipline is preferred.

•Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.

•Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.

Experience Requirements:

6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.

The Ideal Candidate Will

•Investigate and respond to security alerts and incidents escalated by L1 analysts.

•Perform advanced threat analysis, triage, containment, eradication, and recovery activities.

•Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.

•Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.

•Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.

•Lead incident investigations and provide detailed root cause analysis (RCA).

•Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.

•Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).

•Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.

•Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.

•Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.

•Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.

•Participate in post-incident reviews and recommend security control improvements.

•Support compliance, audit, and reporting requirements related to security operations.

Roles & responsibilities

We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team.



The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.

Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)

Educational Qualifications:

•Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.

•Master's degree in Cybersecurity, Information Security, or related discipline is preferred.

•Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.

•Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.

Experience Requirements:

6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.

The Ideal Candidate Will

•Investigate and respond to security alerts and incidents escalated by L1 analysts.

•Perform advanced threat analysis, triage, containment, eradication, and recovery activities.

•Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.

•Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.

•Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.

•Lead incident investigations and provide detailed root cause analysis (RCA).

•Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.

•Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).

•Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.

•Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.

•Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.

•Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.

•Participate in post-incident reviews and recommend security control improvements.





•Support compliance, audit, and reporting requirements related to security operations.

Roles & responsibilities

We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.

Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)

Educational Qualifications:

•Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.

•Master's degree in Cybersecurity, Information Security, or related discipline is preferred.

•Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.

•Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.

Experience Requirements:

6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.

The Ideal Candidate Will

•Investigate and respond to security alerts and incidents escalated by L1 analysts.

•Perform advanced threat analysis, triage, containment, eradication, and recovery activities.

•Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.

•Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.

•Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.

•Lead incident investigations and provide detailed root cause analysis (RCA).

•Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.

•Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).

•Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.

•Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.

•Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.

•Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.

•Participate in post-incident reviews and recommend security control improvements.

•Support compliance, audit, and reporting requirements related to security operations.

📌 Security Operations Center - Assistant Manager (Noida)
🏢 KPMG Global Services
📍 Noida

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security operations center - assistant manager (noida) / noida

Subscribe to this job alert:

Get the latest job offers by email for: security operations center - assistant manager (noida) / noida